System for secure optical transmission of binary code

ABSTRACT

An optical binary code transmission system comprising a sender comprising: means for generating a light beam; phase-shifter means; attenuator means whereby the intensity of the lateral modes is sufficiently low for there to exist at the most only one photon in the lateral modes. The phase-shifter means of the sender impose a phase-shift that is chosen randomly to be equal either to 0 or to π/2 for a first bit value or either to π/or to 3π/2 for a second bit value, and the receiver comprising means for detecting the presence of a photon in the first lateral mode and means for detecting the presence of a photon in the second lateral mode, a first bit value being detected if the presence of a photon is detected in the first lateral mode and a second bit value being detected if the presence of a photon is detected in the second lateral mode.

GENERAL TECHNICAL FIELD

[0001] The present invention relates to a system for the secure optical transmission of binary code.

[0002] To be more precise, an object of the system is to improve on an existing quantum method of distributing encryption keys using modulation sidebands and the quantum properties of light. The ultimate objective is to make a transmission line secure independently of the time and of the computation power available to a spy.

[0003] In theory, a transmission line is absolutely confidential if the signal carrying information is encrypted by addition using a random encryption key employing an exclusive-OR operator. The code sent in this way is impossible to decrypt if the key, which is the same length as the message to be decrypted, is used only once. However, the encryption algorithm makes sense only if the key shared by the legitimate parties is totally secret, which is impossible to achieve using conventional methods of exchanging keys.

[0004] The laws of quantum mechanics offer the possibility of solving this problem by unconditionally secure transmission of the encryption key.

DESCRIPTION OF THE PRIOR ART

[0005] Many protocols for sharing keys have been envisaged that code each bit of a key using a quantum state of a photon.

[0006] The earliest [1] was described by Bennett et al., who propose an exchange protocol with four states forming two conjugate bases, usually referred to as a “4-state protocol” or a “BB84 protocol”. A second protocol [2], also described by Bennett, and usually called a “2-state protocol” or a “B92 protocol”, consists in coding the bits of the key using two non-orthogonal states. The B92 protocol is less secure than the BB84 protocol, however. This is one problem addressed by the present invention.

[0007] In both protocols, a sender (Alice) prepares a photon in a quantum state chosen randomly from the available states. A receiver (Bob) analyses each state of the incident photons by means of a quantum measurement. If a spy (Eve) attempts to eavesdrop on the secret transmission line, she must perform a quantum measurement on the state of the photons sent by Alice, thereby disturbing that state. The spy will inevitably introduce transmission errors that can be detected by consequential variations in the statistics of the photons received by Bob. Other, more complex exchange schemes based on Einstein, Podolsky, Rosen (EPR) photon transmission or on 3-state coding have also been developed.

[0008] Three techniques have been proposed for preparing the photon in the required quantum states. The first two use the BB84 protocol; the third cannot use this protocol in the current state of the art.

[0009] A first technique [3] uses the polarization state of the photon. On transmission, a “1” bit can be represented by a vertical polarization or a right-hand circular polarization and a “0” bit by a horizontal polarization or a left-hand circular polarization. On reception, Bob chooses randomly, and independently of Alice, the base for analyzing the incident photon. Detection of the photon indicates the value of the bit sent.

[0010] A second technique [4] is described in U.S. Pat. No. 5,307,410 and uses an optical time-delay to code the information. Alice and Bob use unbalanced fiber interferometers respectively to introduce and to measure the optical time-delay. Each bit is represented randomly by two values of the optical time-delay. That system thus exploits the property of single-photon interference in the time domain. Each interferometer has in one of its arms an optical phase-shifter for transmitting the key. The pulses propagate in both arms of the interferometer and do not have the same intensity: accordingly, two pulses separated by a time-delay Δt are observed at the output of the first interferometer. One pulse is a reference pulse with a standard intensity. The other pulse is a signal pulse, on average contains fewer than one photon, and has undergone a phase-shift controlled by Alice. Three pulses are observed at the output of the second interferometer. The first is of negligible intensity, deriving from the further attenuated signal pulse. The second is the result of superposing the first signal pulse that has been time-delayed (but not attenuated) and the reference pulse that has been attenuated and phase-shifted by Bob. The intensity of the second pulse therefore depends on both of the phase-shifts as introduced by Bob and Alice, and is used to obtain an encryption key. The third and last pulse is a portion of the reference pulse that has been further delayed and whose intensity is constant. It is used to determine whether the line has been spied on.

[0011] In a third technique [6], which is the subject matter of French Patent Application No. 97 05573 and European Patent Application No. EP 0 877 508 A1, Alice codes each bit of the key on an optical frequency whose phase Φ_(A) is chosen randomly between two values. Bob modulates the light at the same frequency with a second phase Φ_(B) chosen independently of Alice. By exploiting the properties of single-photon interference in the modulation sidebands, Bob is able to determine the quantum state of the incident photons. Among other things, this transmission method can use standard electro-optical components. It is compact, which minimizes the effects of external instability. Accordingly, it can be installed on a standard network.

[0012] The foregoing techniques nevertheless have several drawbacks.

[0013] In the case of the first technique, the polarization must be rigorously maintained throughout transmission. This requires the use of polarization-maintaining fibers, which are not installed in existing networks. A second solution that can be envisaged is to control the polarization along the transmission path. This solution complicates the system enormously as it is necessary to control the fluctuation in polarization regularly, a consequence of which is to reduce the bit rate of the key.

[0014] Distribution systems based on the second technique use a pair of interferometers (transmitter/receiver interferometers) with long arms. The problem is to maintain the time-delay constant between the two arms with great accuracy and despite thermal and mechanical instabilities.

[0015] In the case of the third technique, only the 2-state B92 protocol can be used with the proposed configuration (unlike the first two techniques, which use the 4-state BB84 protocol). The 2-state protocol is less secure than the 4-state protocol. In other words, the confidentiality of the transmission is lower than can be achieved with the BB84 protocol, which in principle guarantees infinite security.

SUMMARY OF THE INVENTION

[0016] The invention proposes to alleviate this last, major drawback and to improve on the system described in the document FR 97 05573 by enabling it to use the 4-state protocol.

[0017] Thus the invention proposes an optical binary code transmission system comprising a sender, a receiver and a transmission line between said sender and said receiver, the sender comprising:

[0018] means for generating an amplitude modulated light beam, which produces a central mode and first and second lateral modes,

[0019] phase-shifter means for imposing a phase-shift on the modulation that is a function of the binary code to be transmitted, and

[0020] means for attenuating the intensity of the modulated light beam so that the intensity of the lateral modes is sufficiently low for there to exist at the most only one photon per pulse in the lateral modes,

[0021] and the receiver comprising:

[0022] means for modulating the light signal synchronously with the modulation applied by the sender and with no phase-shift,

[0023] means for imposing on said modulation a randomly chosen phase-shift equal to one or the other of the phase-shift values that can be imposed by the sender, and

[0024] means for detecting the presence of a photon in the lateral modes after modulation of the received light signal,

[0025] which system is characterized in that

[0026] the phase-shifter means of the sender impose a phase-shift that is chosen randomly to be equal either to 0 or to π/2 for a first bit value or either to π or to 3π/2 for a second bit value,

[0027] and in that

[0028] the detector means of the receiver include means for detecting the presence of a photon in the first lateral mode and means for detecting the presence of a photon in the second lateral mode, a first bit value being detected if the presence of a photon is detected in the first lateral mode and a second bit value being detected if the presence of a photon is detected in the second lateral mode.

[0029] The invention advantageously has the following additional features, either individually or in any feasible combination:

[0030] the sender includes:

[0031] a light source for generating a light beam of given intensity and angular frequency (ω₀),

[0032] means for producing a first amplitude modulation electrical signal,

[0033] means for applying a phase-shift (Φ_(A)) to said first modulation electrical signal, and

[0034] means for modulating the light beam by said phase-shifted first modulation electrical signal,

[0035] and the receiver includes:

[0036] means for producing a second modulation electrical signal,

[0037] means for applying to said second modulation electrical signal a second phase-shift (Φ_(B)) chosen randomly and independently of (Φ_(A)), and

[0038] means for modulating the received light beam by the modulated electrical signal;

[0039] the detector means at each output include filter means and a single-photon photodetector;

[0040] the filter means include a Fabry-Pérot spectrometer;

[0041] the attenuator means attenuate the luminous intensity of the modulated beam so that there is on average not more than 0.1 photon per pulse in each modulation sideband;

[0042] the system further includes means for synchronizing the two electrical modulation signals; and

[0043] the transmitter and the receiver operate independently.

DESCRIPTION OF THE DRAWINGS

[0044] Other advantages and features emerge from the following description, which is purely illustrative, in no way limiting on the invention, and should read with reference to the accompanying drawings, in which:

[0045]FIG. 1 is a theoretical diagram of a quantum transmission system based on generating single sidebands (SSB),

[0046]FIG. 2 shows an amplitude spectrum obtained at the output of a first modulator,

[0047]FIG. 3 shows an amplitude spectrum resulting from a second modulator applying modulation independently of the first modulator,

[0048]FIG. 4 shows intensity spectra of light that has passed through both modulators,

[0049]FIG. 4(a) shows the intensity spectrum for a phase-shift |Φ_(A)−Φ_(B)| equal to 0,

[0050]FIG. 4(b) shows the intensity spectrum for a phase-shift |Φ_(A)−Φ_(B)| equal to π,

[0051]FIG. 4(c) shows the intensity spectrum for a phase-shift |Φ_(A)−Φ_(B)| equal to π/2,

[0052]FIG. 5 shows a key transmission system constituting a first embodiment of the invention with two electro-absorbant modulators,

[0053]FIG. 6 is a diagram showing one embodiment of a quantum key transmission system with one electro-absorbant modulator and one Mach-Zehnder modulator,

[0054]FIG. 7 shows experimental power spectral densities obtained with a scanning Fabry-Pérot interferometer for different values of the relative phase-shift ΔΦ between Alice and Bob,

[0055] in FIG. 7(a), Alice and Bob are in phase opposition,

[0056] in FIG. 7(b), Alice and Bob are in phase quadrature,

[0057] in FIG. 7(c), Alice and Bob are in phase,

[0058]FIG. 8 shows a quantum key transmission system with two Mach-Zehnder modulators,

[0059]FIG. 9 shows experimental power spectral densities obtained with a scanning Fabry-Pérot interferometer for various values (0, π/2 and π) of the relative phase-shift ΔΦ between Alice and Bob, and

[0060]FIG. 10 shows the number of strikes induced by the presence of photons in the modulation sidebands as a function of the relative phase shift ΔΦ=|Φ₁−Φ₂| when the latter varies over the range −π to π.

DESCRIPTION OF EMBODIMENTS AND USES OF THE INVENTION Summary of the Principle of the Distribution Protocol

[0061] The sharing of a common secret key between Alice and Bob includes three consecutive steps which guarantee that the key is absolutely secure:

[0062] (i) On transmission, Alice sends a sequence of photons, choosing randomly the quantum state in which each photon is prepared. The correspondence between each value of a bit and each quantum state is publicly known.

[0063] ii) On reception, Bob decides to measure the state of the incident photon randomly and independently of Alice.

[0064] iii) After quantum transmission, Alice and Bob disclose on a public channel the bases in which the photons were prepared without giving the value of the bits received. This exchange enables any inconclusive measurements effected by Bob to be set aside. By “inconclusive measurements” is meant those that do not indicate with certainty the state of the incident photon at Bob's receiver. In an ideal case, after the public exchange, Alice and Bob share an unprocessed and completely secret key. Under real-life transmission conditions, the encryption key contains errors due to channel noise and the possible intrusion of a spy. An error detection and correction procedure and a process for amplifying the confidentiality then complement quantum transmission as such.

The 4-State Protocol

[0065] The proposed system uses the 4-state (BB84) protocol described by Bennett et al. That protocol proceeds as follows:

[0066] On transmission, Alice chooses four quantum states {|u>,|{overscore (u)}>,|v>,|{overscore (v)}>} that respectively represent the bits {1, 0, 1, 0}. The quantum states selected conform to the following conditions:

<{overscore (u)}|u>=<{overscore (v)}|v>=0,<u|u>=<v|v>=<{overscore (u)}|{overscore (u)}>=<{overscore (v)}|{overscore (v)}>=1  (1)

[0067] $\begin{matrix} {\langle{{\overset{\_}{u}{v\rangle}^{2}} = {\langle{{\overset{\_}{v}{u\rangle}^{2}} = {\langle{{\overset{\_}{v}{\overset{\_}{u}\rangle}^{2}} = {\langle{{u{v\rangle}^{2}} = \frac{1}{2}}}}}}}}} & (2) \end{matrix}$

[0068] Equation (1) indicates that the bases {|u>,|{overscore (u)}>} and {|v>,|{overscore (v)}>} are orthonomic. Equation (2) indicates that the two bases are conjugate.

[0069] On reception, Bob chooses the base for a quantum measurement randomly and independently of Alice. Two situations arise:

[0070] (i) Bob uses the same measurement base that Alice used for preparation. The measurement is then deterministic and Bob knows unequivocally the value of the bit transmitted.

[0071] (ii) Bob uses the base conjugate to that Alice used for preparation. The measurement yields a random result. A “1” bit and a “0” bit are therefore equally probable. The measurement is therefore inconclusive.

[0072] When the transmission of photons has terminated, Bob discloses to Alice, over a public channel, the measurement base for each photon received. The result of the measurement naturally remains secret. By this method Alice and Bob eliminate all inconclusive results. Finally, they share a random sequence of bits that can be used as an encryption key.

[0073] If a spy, Eve, attempts to eavesdrop on the quantum transmission line, she will have to carry out the same type of measurement as Bob. She has only one chance in two of choosing the same base as Alice and obtaining a conclusive result. Also, she must return the purloined photon if she does not wish to be detected. According to the theory of quantum measurement, the photon will be in the same quantum state as the original state if Eve has used the correct base. If not, there is a 50% chance of the spy returning the photon in the wrong quantum state. Alice and Bob publicly compare a portion of the bits exchanged (constituting a bit sequence that is intentionally sacrificed) to test the quantum line. Thus Eve will be detected by the errors generated by her presence.

Description of a General System Example

[0074]FIG. 1 shows a transmission system implementing the protocol outlined above. The system includes:

[0075] A) a sender (Alice) including:

[0076] a photon source 1, which can be a strongly attenuated laser diode and whose spectrum is centered on an optical frequency ω₀.

[0077] a frequency generator VCO_(A) 6 that delivers an electrical signal taking the form V′_(A)=m cos Ωt.

[0078] a phase-shifter 8 that shifts the phase of the signal V′_(A) by an amount Φ_(A) to yield at its output a control signal V_(A)=m cos(Ωt+Φ_(A)) that is applied to the modulation component 2, which is a phase-shifter controlled by the bits of the key to be transmitted in accordance with the protocol:

[0079] bit 1: Φ_(A)=0 or π/2,

[0080] bit 0: Φ_(A)=π or 3π/2,

[0081] the values of ΦA being chosen randomly between 0 and π/2 for the “1” bit and between π and 3π/2 for the “0” bit.

[0082] a modulation component 2 for which the expression for the amplitude modulation curve is H_(A). The modulation produces in the light beam two modulation sidebands ω₀±Ω.

[0083] an attenuator that attenuates the light beam so that there is only one photon in the sidebands.

[0084] B) a receiver (Bob) including:

[0085] a frequency generator VCO_(B) 7 that delivers an electrical signal taking the form V′_(B)=m cos Ωt.

[0086] a phase-shifter 9 that shifts the phase of the signal V′_(B) by an amount Φ_(B) to yield at its output a control signal V_(B)=m cos(Ωt+Φ_(B)) for the modulation component 4, the phase Φ_(B) being chosen randomly and independently of Alice between 0 and π/2.

[0087] a second modulation component 4 for which the expression for the amplitude modulation curve is H_(B).

[0088] means 10 for optically splitting the light beam from the component 4 to obtain two outputs.

[0089] filter components 15 and 16 that optically split each of the two modulation sidebands to obtain at each output of the device a single sideband ω₀±Ω.

[0090] photodetectors 11 and 12 at the outputs 13 and 14, respectively, receiving each of the sidebands. The signals delivered by each of the photodetectors depend on the phase difference |Φ_(A)−Φ_(B)| and are complementary to each other:

[0091] a “1” bit is obtained when a photon is detected at the output 13,

[0092] a “0” bit is obtained when a photon is detected at the output 14.

[0093] means for transmitting the photons 3 via an optical fiber.

[0094] means 23 for synchronizing the frequency generators VCO_(A) and VCO_(B).

[0095] Alice and Bob have means 20 and 21 for communicating with each other via a public channel 17. The receiver informs the sender via this channel which phases were used without revealing on which photodetector the photons were detected.

Theory of Operation

[0096] The intensities of the modulation sidebands created in this way after Bob vary in a complementary manner as a function of the phase-shift induced between Alice and Bob if H_(A) and H_(B) conform to a given necessary but sufficient condition. The expression for this condition is described in detail hereinafter. To simplify the mathematics, the following description is given by way of illustration for an example in which the modulation curves H_(A) and H_(B) have linear rising and falling edges. This situation, which physically corresponds to “small signals”, allows the use of a development limited to the first order, and is in no way limiting on the invention. The modulation curves can also have non-linear edges.

[0097] The source 1 is a quasi-monochromatic laser diode of frequency ω₀. Note that this source can be an impulse source or, in a different embodiment, a continuous source; it can be a single-frequency or quasi-monochromatic source. The amplitude of the signal is written as follows:

E ₀(t)=|E ₀ |e ^(jω) ^(₀) ^(t)  (3)

[0098] Alice's sender 2 consists of a light modulation system whose amplitude modulation curve H_(A) is of the following first order form: $\begin{matrix} {{H_{A}\left( V_{A} \right)} \approx {\frac{1}{2}\left( {1 + {K_{A}V_{A}}} \right)}} & (4) \end{matrix}$

[0099] In the above equation, K_(A) is an electro-optical coefficient characterizing the component used and V_(A) is an electrical control signal is of low amplitude and frequency Ω. It is generated by the local oscillator VCO_(A). This signal is phase-shifted by an amount Φ_(A) relative to the center frequency ω₀: V_(A)=m cos(Ωt+Φ_(A)) The constant K_(A) is generally expressed as follows:

K _(A) =Kexpjψ _(A)  (5)

[0100] The optical signal K_(A)(t) after the transmitter then consists of the center frequency ω₀ and two modulation sidebands ω₀±Ω phase-shifted Φ_(A) relative to ω₀, as indicated by equation (6): $\begin{matrix} {{E_{A}(t)} \approx {{E_{0}}\exp \quad {j\omega}_{0}{t\left\lbrack {1 + {\frac{Km}{2}\exp \quad {j\psi}_{A} \times \exp \quad {j\left( {{\Omega \quad t} + \Phi_{A}} \right)}} + {\frac{Km}{2}\exp \quad {j\psi}_{A} \times \exp} - {j\left( {{\Omega \quad t} + \Phi_{A}} \right)}} \right\rbrack}}} & (6) \end{matrix}$

[0101] Thus at the output of the first modulator there is obtained one modulation band ω₀+Ω with a phase V_(A)+Φ_(A) and another modulation band ω₀−Ω with a phase V_(A)−Φ_(A) (FIG. 2).

[0102] Bob's receiver 3 consists of a second light modulation system. It has an amplitude modulation curve H_(B) whose first order development is written: $\begin{matrix} {{H_{B}\left( V_{B} \right)} \approx {\frac{1}{2}\left( {1 + {K_{B}V_{B}}} \right)}} & (6) \end{matrix}$

[0103] K_(B) is an electro-optical coefficient characterizing the component used and V_(B) is an electrical control signal with the same amplitude and the same frequency Ω, but phase shifted by Φ_(B): V_(B)=m cos(Ωt+Φ_(B)) The constant K_(B) is generally expressed as follows:

K _(B) =Kexpjψ _(B)  (7)

[0104] The second modulator operates in accordance with the same principles as the first modulator.

[0105]FIG. 3 shows the two modulation sidebands generated. The phases are ψ_(B)+Φ_(B) for the band ω₀−Ω and ψ_(B)−Φ_(B) for the band ω₀−Ω.

[0106] If the two modulators operate simultaneously, the amplitude E_(B)(t) of the signal at the output of the second modulator comprises the second frequency ω₀ and the modulation sidebands. Their intensity depends on the relative phase ΔΦ=|Φ_(A)−Φ_(B)|: $\begin{matrix} {{E_{B}(t)} \approx {\frac{{E_{0}}\exp \quad {j\omega}_{0}}{4}\left\lbrack {1 + {\frac{Km}{2}\exp \quad {j\Omega}\quad t \times \left( {{\exp \quad {j\psi}_{B}\exp \quad j\quad \Phi_{B}} + {\exp \quad j\quad \psi_{A}\exp \quad {j\Phi}_{A}}} \right)} + {\frac{Km}{2}\exp} - \quad {{j\Omega}\quad t \times \left( {{\exp \quad {j\psi}_{B}\exp} - {j\quad \Phi_{B}} + {\exp \quad {j\psi}_{A}\exp} - {j\Phi}_{A}} \right)}} \right\rbrack}} & (8) \end{matrix}$

[0107] The spectral power density at the output of Bob's analysis system therefore comprises the center frequency and two modulation sidebands ω₀±Ω with the following intensities: $\begin{matrix} {I \approx \frac{{E_{0}}^{2}}{16}} & (10) \\ {i_{\omega_{0} + \Omega} \approx {\frac{K^{2}m^{2}{E_{0}}^{2}}{32}\left( {1 + {\cos \left( {\Phi_{B} - \Phi_{A} + \psi_{B} - \psi_{A}} \right)}} \right)}} & (9) \\ {i_{\omega_{0} - \Omega} \approx {\frac{K^{2}m^{2}{E_{0}}^{2}}{32}\left( {1 + {\cos \left( {\Phi_{B} - \Phi_{A} + \psi_{B} - \psi_{A}} \right)}} \right)}} & (10) \end{matrix}$

[0108]FIG. 4 shows that the intensities of the modulation sidebands depend on the relative phase difference |Φ_(A)−Φ_(B)|. The intensities i_(ω) ₀ _(+Ω) and i_(ω) ₀ _(−Ω) are complementary if the amplitude transfer curves H_(A) and H_(B) satisfy, for any phase difference |Φ_(A)−Φ_(B)|, the condition: $\begin{matrix} {{{\psi_{B} - \psi_{A}} = \frac{\left( {{2k} + 1} \right)\pi}{2}},{\forall{k \in N}}} & (13) \end{matrix}$

[0109] In this case, the intensities i_(ω) ₀ _(+Ω) and i_(ω) ₀ _(−Ω) are simply written: $\begin{matrix} {i_{\omega_{0} + \Omega} \approx {\frac{K^{2}m^{2}{E_{0}}^{2}}{32}{\cos^{2}\left\lbrack {\left( {\Phi_{B} - \Phi_{A}} \right)/2} \right\rbrack}}} & (11) \\ {i_{\omega_{0} - \Omega} \approx {\frac{K^{2}m^{2}{E_{0}}^{2}}{32}{\sin^{2}\left\lbrack {\left( {\Phi_{B} - \Phi_{A}} \right)/2} \right\rbrack}}} & (12) \end{matrix}$

[0110] If Alice and Bob are in phase, the modulation sideband ω₀+Ω is at a maximum and the other sideband ω₀−Ω is non-existent (in other words, a single sideband (SSB) ω0+Ω is produced). If Alice and Bob are in phase quadrature, the two modulation sidebands are present with an intensity that is half the maximum intensity. If Alice and Bob are in phase opposition, the modulation sideband ω₀−Ω is at maximum and the other sideband ω₀+Ω is non-existent (i.e. a single sideband (SSB) ω₀−Ω is produced).

[0111] After Bob, a spectral filter system, for example two Fabry-Pérot interferometers, splits the two modulation sidebands and directs the band ω₀+Ω to the output 1 and the band ω₀−Ω to the output 2. There is a detector at each output.

[0112] Under quantum conditions, Alice strongly attenuates the beam behind her modulation system to obtain approximately 0.1 photon per pulse in each modulation sideband. This generates one photon every ten pulses and limits the number of pulses likely to have more than one photon. According to the quantum theory of measurement, equations (11) to (15) can then be translated in terms of the probability of detecting a photon in one of the modulation sidebands.

Transmission Procedure

[0113] Transmission proceeds as follows:

[0114] The bases used by Alice are: {0,π} and {π/2, 3π/2}. They have the properties defined by equations 1 and 2. Alice chooses a phase Φ_(A) and sends the photon to Bob.

[0115] Bob chooses randomly and independently of Alice the phase value Φ_(B) between 0 and π/2 to carry out his measurement. Accordingly to equations (14) and (15), the measurement has three possible outcomes:

[0116] ΔΦ=0: the photon is detected at output 1. This output corresponds to a “1” bit.

[0117] ΔΦ=π: the photon is detected at output 2. This output corresponds to a “0” bit.

[0118] ΔΦ=π/2: the photon is detected at output 1 or at output 2 with the same probability (indeterminate measurement).

[0119] The transmission protocol is summarized in Table 1, in which “?” indicates an indeterminate measurement. TABLE 1 Phase 0 π π/2 3π/2 chosen by Alice Bit sent 1 0 1 0 by Alice Phase 0 π/2 0 π/2 0 π/2 0 π/2 chosen by Bob Outputs 12⁽¹⁾ ? (12²) ? ? 12⁽¹⁾ ? (12²) activated Public 1 ? 0 ? ? 1 ? 0 comparison

[0120] Any pair of modulation systems whose amplitude modulation curves are defined by equations (4) and (7) and whose arguments conform to the phase relationship specified in equation (13) can be used for SSB quantum transmission of encryption keys. Thus three embodiments of a quantum transmission system using SSB generation can be described. Others can obviously be envisaged. The following examples are in no way limiting on the invention.

First Preferred Embodiment

[0121]FIG. 5 shows a first embodiment using two electro-absorbant modulators.

[0122] The source 1 is a distributed feedback (DFB) laser diode emitting at 1550 nm, having a center frequency ω₀. Its spectral width is equal to 30 MHz. Alice's sender is an electro-absorbant modulator 2 with a bandwidth of 2.5 Gbit/s controlled by a sinusoidal electrical signal with a frequency Ω of 2.5 GHz. This signal is generated by a local oscillator VCO_(A) 12 whose phase Φ_(A) is fixed randomly by a phase-shifter 13 from four values (0, π) or (π/2, 3π/2). The values 0 and π/2 code a “1” bit and the values π and 3π/2 code a “0” bit.

[0123] Alice then attenuates the beam to obtain 0.1 photon per pulse on average for each modulation sideband, using a calibrated attenuator 3.

[0124] The transmission channel 4 is 30 km of 1550 nm monomode optical fiber.

[0125] Bob's modulation system is identical to that of Alice. It comprises an electro-absorbant modulator 5 controlled by a second local oscillator VCO_(B) 14. The electrical signal is generated at the same frequency Ω but with a phase equal to Φ_(B) whose value can be chosen randomly and independently of Alice from 0 to π/2 by a phase-shifter 15. The operating point of each modulator is fixed by a constant voltage V₁ and V₂ to obtain the required two modulation curves.

[0126] Conventionally, the spectral density of the signal analyzed after Bob contains the center carrier frequency ω₀ and a single sideband at frequency ω₀−Ω or ω₀+Ω when the relative phase difference |Φ_(A)−Φ_(B)| is equal to 0 or π, respectively. The signal contains both ω₀−Ω and ω₀+Ω if the relative phase difference is equal to ±π/2. The two oscillators VCO_(A) and VCO_(B) are synchronized by means 17.

[0127] Finally, after Bob, a first Fabry-Pérot spectral filter 7 selects one of the two modulation bands, for example ω₀−Ω, which is detected by a photodetector D₁, output 8. The probability P₁ of detecting a photon in this modulation sideband follows the sin² law as a function of the relative phase difference ΔΦ=|Φ_(A)−Φ_(B)| as shown by Equation (10).

[0128] A circulator 6 directs the signal reflected by the filter 7 toward a second Fabry-Pérot filter 10. This passes only the sideband ω₀+Ω, which is detected by a second photodetector D₂, output 11. The probability P₂ of detecting a photon in this modulation sideband follows the cos² law as a function of the relative phase difference ΔΦ=|Φ_(A)−Φ_(B)| as shown by Equation (9). The two outputs have complementary detection probabilities, enabling use of the 4-state protocol previously explained. A counter 9 is connected to the two detectors to evaluate the number of photons emerging from Bob's system as a function of the phase difference |Φ_(A)−Φ_(B)|. Data processing means 16 process the data relating to the counting of the photons and to their time of arrival.

Second Embodiment

[0129]FIG. 6 shows another embodiment of an SSB quantum encryption system with one electro-absorbant modulator and one Mach-Zehnder modulator.

[0130] The source 1 is a (DFB) laser diode emitting at 1550 nm. Its spectral width is equal to 30 MHz. Alice's modulation system is an electro-absorbant modulator 2 identical to the previous one. The transmission channel 3 is 30 km of 1550 nm monomode optical fiber.

[0131] Bob's modulation system 5 is a Mach-Zehnder modulator integrated on lithium niobate. Its half-wave voltage is equal to 5 V for a bandwidth of 5 GHz and insertion losses of 4 dB.

[0132] As previously, the operating point of the modulation systems 12 and 13 of Alice and 14 and 15 of Bob are adjusted to obtain modulation curves H_(A) and H_(B) defined by equations (9) and (10) using DC voltages V₁ and V₂.

[0133] The modulation sidebands are filtered using two fiber Fabry-Pérot interferometers 7 and 10 as before.

[0134] The components 8 and 11 are avalanche photodiodes at each output of Bob's modulation system. A counter 9 is connected to these two detectors to evaluate the number of photons emerging from Bob's system as a function of the phase difference |Φ_(A)−Φ_(B)|. Data processing means 16 process the data relating to the counting of the photons and to their time of arrival.

[0135] The above configuration has been tested in the conventional way, i.e. under non-quantum conditions, to find out if a spectrum comprising modulation sidebands whose intensities vary in a complementary fashion as a function of the relative phase difference is obtained after Bob. The experiment was conducted under the following conditions:

[0136] The laser diode emitted continuously at an optical power of 0 dBm. The two modulators were controlled by radio frequency (RF) electrical signals at a frequency of 2.5 GHz. The peak-to-peak amplitude of the electrical signal applied to Bob's modulator 5 was approximately 1 V, corresponding to a modulation rate m=0.3 rad. The electrical signal applied to Alice's modulator 2 was 600 mV, corresponding to a modulation rate similar to Bob's. The VCO of Alice and Bob were synchronized by means 17. The relative phase difference was applied by means of an electrically controlled phase-shifter having a bandwidth of 1 MHz. One the Fabry-Pérot interferometers was used in scanning mode as a spectrum analyzer. It had a free spectral interval of 10 GHz for a fineness of 100.

[0137]FIG. 4 shows the spectral power density of the signal at the output of Bob's system for various values of the relative phase difference ΔΦ=|Φ_(A)−Φ_(B)|. Each modulation sideband is effectively separated from the center frequency of 2.5 GHz.

[0138]FIG. 7 shows the experimental power spectral densities obtained with a scanning Fabry-Pérot interferometer for various values of the relative phase difference ΔΦ between Alice and Bob. The scale on the horizontal axis is 830 MHz per division. The luminous intensity in arbitrary units is plotted on the vertical axis.

[0139] In FIG. 7(a), Alice and Bob are in phase opposition and the spectrum contains a single sideband corresponding to the frequency ω₀−Ω.

[0140] In FIG. 7(b) Alice and Bob are in phase quadrature and the spectrum contains the two sidebands corresponding to the frequencies ω₀±Ω. In this case, their intensity is equal to half that of the previous single sideband.

[0141] In FIG. 7(c) Alice and Bob are in phase and the spectrum contains the other single sideband corresponding to the frequency ω₀+Ω.

[0142] The system is extremely compact because Alice's modulator and the laser diode are implemented on the same substrate, or wafer, using standard devices available off the shelf. The system has two complementary outputs, enabling encryption keys to be transmitted using the 4-state protocol.

Third Embodiment

[0143]FIG. 8 shows a final embodiment of the SSB quantum encryption system using two Mach-Zehnder modulators.

[0144] The source 1 is a pulsed laser diode with a center frequency of ω₀.

[0145] Alice's sender is an intensity modulator 2 integrated on lithium niobate with unbalanced arms. The optical path difference is set at λ/4 by a DC voltage V_(λ/4).

[0146] The light is therefore modulated at a frequency Ω<<ω₀ with a low depth of modulation m. Alice uses a local oscillator VCO_(A) 12 to generate the electrical modulation signal at the frequency Ω that is phase-shifted by the phase-shifter 13 by an amount Φ_(A) that is chosen randomly and independently of Bob from the four values (0, π/2, −π/2, n). The VCO are synchronized by means 17.

[0147] Alice then attenuates the beam to obtain 0.1 photon per pulse on average for each modulation sideband, using a calibrated attenuator 3.

[0148] The transmission channel 4 is 30 km of standard 1550 nm monomode fiber.

[0149] Bob's receiver comprises a second amplitude modulator 5 integrated on lithium niobate with unbalanced arms. The optical path difference is set at 3λ/4 by a DC voltage V_(3λ/4).

[0150] In this application, the phase relationship given in equation (13) reflects the fact that the slope of the modulation curve of the receiver is opposite to that of Alice. The modulation signal applied to Bob is generated by a second local oscillator VCO_(B) 14 at the same frequency Ω. Its phase is selected by the phase-shifter 15 and is set at (Φ₂+π/2). After Bob there is the same filter system comprising two fiber Fabry-Pérot interferometers 7 and 10.

[0151] Two types of experiment were carried out to verify the operation of the system.

[0152] The first was carried out with a conventional source that was not attenuated.

[0153] The second was carried out under quantum conditions, i.e. with 0.1 photon per pulse on average in each modulation sideband.

[0154] a) Experiment Under Standard Conditions:

[0155] The source 1 was a DFB laser diode emitting at 1550 nm. The diode had a spectral width of 30 MHz. The modulators 2 and 5 were electro-optical modulators integrated on lithium niobate. Their half-wave voltages were equal to 5 V, their bandwidth 5 GHz, and their insertion losses 4 dB. They were controlled by two synchronized local oscillators emitting an RF signal at 2.5 GHz. Their phases Φ₁ and Φ₂ could be changed by means of a phase-shifter having a bandwidth of 1 MHz. The peak-to-peak amplitude of the electrical signals applied to the modulators was 1.6 V, corresponding to a modulation rate m=0.5 rad. One of the Fabry-Pérot interferometers was set to scanning mode and used as a spectrum analyzer. Its spectral width and its free spectral interval were respectively 100 MHz and 10 GHz. The interferometers were thermostatically-controlled and polarization-independent fiber Fabry-Pérot interferometers. The laser diode emitted continuously at a power of 0 dBm. The overall losses of the transmission system were approximately −10 dB (fiber losses of −0.2 dB/km, analyzer losses of −2 dB, and losses in Bob's modulator of −4 dB).

[0156]FIG. 9 shows the spectral densities displayed with the aid of the Fabry-Pérot interferometer for different values of the relative phase difference. The scale on the horizontal axis is 625 MHz per division. The luminous intensity in arbitrary units is plotted on the vertical axis.

[0157] It is clear that the modulation sidebands again vary in the required manner. The system can therefore be used to transmit an encryption key using the 4-state (BB84) protocol.

[0158] b) Experiment Under Quantum Conditions:

[0159] In this configuration, the DFB laser diode generated optical pulses 5 ns wide with a repetition rate of 1 MHz. A calibrated attenuator 3 attenuated the light at the output of Alice's coding system so that the average number of photons per pulse was approximately 0.1 in each modulation sideband. The transmission line was 22 km of 1550 nm monomode fiber. The detectors 8 and 11 were InGaAs/InP avalanche photodiodes used in active gating mode. They were cooled with the aid of a hybrid liquid nitrogen/Peltier module system to a temperature of −100° C. (±0.2° C.) to obtain a stable quantum efficiency. In this example, the quantum efficiency was evaluated at 13%. To test the performance of the system, the visibility V under quantum conditions and the quantum bit error rate (QBER) were evaluated. The procedure for determining the visibility was as follows:

[0160] The number of electrical pulses generated by the avalanche photodiodes in response to the incident photons was studied as a function of the relative phase difference ΔΦ. The value of ΔΦ varied continuously from 0 to 2π. For each value, the number of pulses was accumulated over 1 s. The dark strikes n_(d) of the photodiodes, which correspond to spurious pulses induced by the photodiodes in the absence of light, were evaluated at 8 strikes per second (c/s).

[0161] A counter 9 was connected to the two detectors to evaluate the number of photons emerging from Bob's system as a function of the phase difference |Φ_(A)−Φ_(B)|. Data processing means 16 processed the data relating to the counting of the photons and their time of arrival.

[0162]FIG. 10 shows the number of strikes induced by photons present in the modulation sidebands detected at the outputs 1 and 2 as a function of the relative phase difference. The circles correspond to the experimental measurements obtained at the output 13 in FIG. 1. The continuous line curve is its sin² approximation. The stars correspond to the experimental measurements obtained at the output 14 in FIG. 1. The dashed line curve is its cos² approximation.

[0163] The visibility V of the single-photon interference fringes obtained in this way was of the order of 98% for the two systems of interference fringes corresponding to the two complementary outputs.

[0164] The quantum binary error rate defined in reference [4] is strongly dependent on the visibility V and the number n_(d) of dark strikes of the photodiodes, according to the following equation: $\begin{matrix} {{QBER} = {{2\left( {1 - V} \right)} + \frac{n_{d}}{\frac{1}{2}\left( {{\mu \times \eta \times R \times T \times T_{B}} + {2n_{d}}} \right)}}} & (13) \end{matrix}$

[0165] in which T is the attenuation caused by the fiber (−4 dB over 20 km), T_(B) is the attenuation induced by Bob's receiver (−4 dB in this example), V is the visibility obtained experimentally, and R is the repetition rate of the optical pulses. The factor 1/2 is inherent to the BB84 protocol, since Alice and Bob have one chance in two of choosing the same base for photon preparation and analysis. Finally, from equation (11), the QBER of the system described is equal to 7.2%. That value is sufficiently low to achieve a quantum distribution of the encryption key if the limit QBER is evaluated at 30% for the BB84 protocol (its limit value for the 2-state protocol is evaluated at 10%). When that limit value is reached, the security of the key is no longer absolute.

[0166] In conclusion, SSB encryption enables quantum encryption key transmission over long distances using a 4-state protocol. The degree of security is greatly increased over the previous system using the 2-state protocol (French Patent Application No. 97/05573 and European Patent Application No. 877 508 A1). The systems described have the advantage of being compact and relatively insensitive to thermal or mechanical instability, since they can use the integrated optical technology. Furthermore, these systems can be introduced directly into standard transmission networks.

[0167] Bibliography

[0168] [1] C. H. Bennett, G. Brassard, “Quantum cryptography: Public key distribution and coin tossing”, Proceeding of IEEE International on Computers, Systems and Signal Processing, Bangalore, India, (IEEE New York, 1984), pp.175-179.

[0169] [2] C. H. Bennett, “Quantum cryptography using any two non orthogonal states”, Physical Review Letters, vol.68, no.21, pp.3121-3124, 1992.

[0170] [3] see for example: J. Breguet, A. Muller and N. Gisin, “Quantum cryptography with polarized photons in optical fibers”, Journal of Modern Optics, vol.41, no.12, pp.2405-2412, 1994.

[0171] [4] see for example: P. D. Townsend, “Quantum cryptography on optical fiber networks”, Optical Fiber Technology, vol.4, pp.345-370, 1998.

[0172] G. Ribordy, J. D. Gautier, N. Gisin, O. Guinnard and H. Zbinden, “Fast and friendly quantum key distribution”, Journal of Modern Optics, vol.47, no.213. pp.517-531, 2000.

[0173] [5] P. C. Sun, Y. Mazurenko and Y. Fainman, “Long distance frequency division interferometer for communication and quantum cryptography”, Optics Letters, vol.20, no.9, pp.1062-1064, 1995.

[0174] [6] Y. Mazurenko, J.-M. Merolla, J.-P. Goedgebuer, “Quantum transmission of information with the help of subcarrier frequency. Application to quantum cryptography”, Optics and Spectroscopy, vol.86, no.2, pp.145-147, 1999.

[0175] J. -M. Merolla, Y. Mazurenko, J. -P. Goedgebuer, L. Duraffourg, H. Porte and W. T. Rhodes, “Quantum cryptography device using single-photon phase modulation”, Physical Review A, vol.60, no.3, pp.1899-1905, 1999.

[0176] J. -M. Merolla, Y. Mazurenko, J. -P. Goedgebuer and W. T. Rhodes, “Single-photon interference of phase-modulated light for quantum cryptography”, Physical Review Letters, vol.82, no.8, pp.1656, 1999.

[0177] J. -M. Merolla, Y. Mazurenko, J. -P. Goedgebuer, H. Porte and W. T. Rhodes, “Phase-modulation transmission system for quantum cryptography”, Optics Letters, vol.24, no.2, pp.104, 1999.

[0178] [7] G. H. Smith, D. Novak and Z. Ahmed, “Technique for optical SSB generation to overcome dispersion penalties in fiber-ratio systems”, Electronics Letters, vo.33, no.1, pp.74-75, 1997. 

1. An optical binary code transmission system comprising a sender, a receiver and a transmission line between said sender and said receiver, the sender comprising: means for generating a light beam amplitude modulated at a given modulation frequency, which produces a central mode and first and second lateral modes, phase-shifter means for imposing a phase-shift on the modulation that is a function of the binary code to be transmitted, and means for attenuating the intensity of the modulated light beam so that the intensity of the lateral modes is sufficiently low for there to exist at the most only one photon in the lateral modes, and the receiver comprising: means for modulating the light signal synchronously with the modulation applied by the sender and with no phase-shift, means for imposing on said modulation a randomly chosen phase-shift equal to one or the other the phase-shift values that can be imposed by the sender, means for detecting the presence of a photon in the lateral modes after modulation of the received light signal, which system is characterized in that the phase-shifter means of the sender impose a phase-shift that is chosen randomly to be equal either to 0 or to π/2 for a first bit value or either to π or to 3π/2 for a second bit value, and in that the detector means of the receiver include means for detecting the presence of a photon in the first lateral mode and means for detecting the presence of a photon in the second lateral mode, a first bit value being detected if the presence of a photon is detected in the first lateral mode and a second bit value being detected if the presence of a photon is detected in the second lateral mode.
 2. A system according to claim 1, characterized in that the sender (A) includes: a light source (1) for generating a light beam of given intensity and angular frequency (ω₀), means (6) for producing a first amplitude modulation electrical signal, means (8) for applying a phase-shift (Φ_(A)) to said first modulation electrical signal, and means (2) for modulating the light beam by said phase-shifted first modulation electrical signal, and the receiver (B) includes: means (7) for producing a second modulation electrical signal, means (9) for applying to said second modulation electrical signal a second phase-shift (Φ_(B)) chosen randomly and independently of (Φ_(A)), and means (4) for modulating the received light beam by the modulated electrical signal.
 3. A system according to claim 1, characterized in that the detector means at each output (11, 12) include filter means (15, 16) and a single-photon photodetector.
 4. A system according to claim 3, characterized in that the filter means include a Fabry-Pérot spectrometer.
 5. A system according to claim 1, characterized in that the attenuator means (2′) attenuate the luminous intensity of the modulated beam so that there is on average at most 0.1 photon per pulse in each modulation sideband.
 6. A system according to claim 1, characterized in that it further includes means (13) for synchronizing the two electrical modulation signals.
 7. A sender for a system according to any one of claims 1 to 6, characterized in that it comprises: means for generating an amplitude modulated light beam, which produces a central mode and first and second lateral modes, phase-shifter means for imposing a phase-shift on the modulation that is a function of the binary code to be transmitted, which phase-shift is chosen randomly to be equal either to 0 or to π/2 for a first bit value or either to π or to 3π/2 for a second bit value, means for attenuating the intensity of the modulated light beam so that the intensity of the lateral modes is sufficiently low for there to exist at the most only one photon per pulse in the lateral modes.
 8. A receiver for a system according to any one of claims 1 to 6, characterized in that it comprises: means for modulating the light signal synchronously with the modulation applied by the sender and with no phase-shift, means for imposing on said modulation a randomly chosen phase-shift equal to one or the other the phase-shift values that can be imposed by the sender, with means for detecting the presence of a photon in the lateral modes after modulation of the received light signal, means for detecting the presence of a photon in the first lateral mode and means for detecting the presence of a photon in the second lateral mode, a first bit value being detected if the presence of a photon is detected in the first lateral mode and a second bit value being detected if the presence of a photon is detected in the second lateral mode.
 9. A method of optical transmission of binary code between a sender and a receiver wherein the sender: generates an amplitude modulated light beam, which produces a central mode and first and second lateral modes, imposes a phase-shift on the modulation that is a function of the binary code to be transmitted, and attenuates the intensity of the modulated light beam so that the intensity of the lateral modes is sufficiently low for there to exist at the most only one photon per pulse in the lateral modes, the receiver: modulates the light signal synchronously with the modulation applied by the sender and with no phase-shift, imposes on said modulation a randomly chosen phase-shift equal to one or the other the phase-shift values that can be imposed by the sender, and detects the presence of a photon in the lateral modes after modulation of the received light signal, which system is characterized in that the sender imposes a phase-shift that is chosen randomly to be equal either to 0 or to π/2 for a first bit value or either to π or to 3π/2 for a second bit value, and in that the receiver detects the presence of a photon in the first lateral mode and the presence of a photon in the second lateral mode, a first bit value being detected if the presence of a photon is detected in the first lateral mode and a second bit value being detected if the presence of a photon is detected in the second lateral mode, and in that the sender and the receiver sacrifice, by comparing them, some of the values of the bits transmitted to detect the errors induced by incorrect transmission or unwanted eavesdropping by a spy on the transmission line.
 10. A method according to claim 9, characterized in that the sender and the receiver synchronize their modulation electrical signals. 